How VAYRO handles client confidentiality, intellectual property, and discretion. Written down so that leadership teams, general counsel and information security teams can read our position in one place before we meet.
The standards we operate to
Every engagement is covered by a mutual non-disclosure agreement before any client information leaves the room. We operate under UK GDPR and the Data Protection Act 2018 as a data controller for our own records and as a data processor when handling client personal data on their behalf. Client information is stored on UK and EU infrastructure by default, with access limited to the named engagement team on a least privilege basis. We do not use client data to train third party models. We do not repurpose client materials into public case studies without written permission, and we will decline to name a client publicly if that is what the leadership team prefers.
What this means in practice
You can talk to a VAYRO practitioner in the same way you would talk to a trusted internal senior. Board level material is treated as board level material. Strategic AI plans are handled as strategic AI plans, not conference talks. Where a client works in a regulated sector, such as financial services under the FCA or healthcare under the CQC and NHS Digital, we align our operating standards to the regulatory expectations that already govern their business. For further reading see the Privacy Policy, Terms of Use and Accessibility Statement. To open a confidential conversation, use Work with VAYRO.